Of all the documents a customer asks a supplier for, the sub-processor list is the one they read most carefully, because it is the one they can check. Every entry names a company they can look up, a country they have a view on, and a claim about a contract they can ask you to produce. It is also the document most small suppliers get wrong, usually by naming tools instead of companies.
This is how to write one that survives a reviewer, with a template you can copy and twelve entries you probably need.
If you process personal data on a customer's behalf (you are their processor), then any third party you use that also touches that data is a sub-processor. Your hosting provider, your email service, your CRM, your payment processor, your AI API. Under Article 28(2) GDPR you need the customer's prior authorisation for them, general or specific, and under 28(4) you are liable to the customer for what they do.
Not sub-processors: tools that handle only your own data (your accountant, your payroll provider, for the customer's purposes), and independent controllers you disclose data to on their own account. The line is whether the third party processes the customer's personal data on your instructions. Analytics on your marketing site is your business as a controller; analytics inside the product you run for the customer is a sub-processor.
Entities and transfer mechanisms as recorded in Rowpa's vendor library on 4 September 2026; regions are the ones commonly configured. Check your own account settings and each vendor's current DPA before you publish.
| Tool | Legal entity | Purpose | Hosting | Agreement and transfer |
|---|---|---|---|---|
| Supabase | Supabase Inc. (US) | Database and auth | EU, Frankfurt (region you choose) | DPA accepted in dashboard; SCCs |
| Vercel | Vercel, Inc. (US) | Application hosting | Global edge, EU region configurable | DPA in terms; DPF with UK Extension |
| Stripe | Stripe, Inc. (US) | Payments | EU and US | DPA in terms; SCCs and DPF |
| Mailchimp | Intuit Inc. (US) | Email marketing | US | DPA in terms; SCCs and DPF |
| Resend | Resend Inc. (US) | Transactional email | US, EU region available | DPA in terms; SCCs |
| HubSpot | HubSpot, Inc. (US) | CRM | US, EU data centre available | DPA in terms; SCCs and DPF |
| Google Workspace | Google LLC (US) | Email, documents | Global, EU data regions available | DPA in terms; SCCs and DPF |
| Microsoft 365 | Microsoft Corporation (US) | Email, documents | EU Data Boundary available | DPA in terms; SCCs and DPF with UK Extension |
| Xero | Xero Limited (NZ) | Accounting | AWS, region per account | DPA in terms; SCCs (NZ also holds adequacy) |
| Anthropic | Anthropic, PBC (US) | AI drafting (API) | Confirm account processing locations | Verify executed DPA and applicable transfer safeguards |
| OpenAI | OpenAI, Inc. (US) | AI features (API) | Confirm account processing locations | Verify executed DPA and applicable transfer safeguards |
| Cloudflare | Cloudflare, Inc. (US) | CDN and DNS | Global edge | DPA in terms; SCCs and DPF |
Most customer DPAs grant general authorisation on condition that you keep a current list somewhere they can see it and tell them before you add a sub-processor, with a window (often 30 days) to object. So the list needs a home with a date on it, and a way to notify. The usual shape is a public page with the current list, a version history, and an email to customers who have asked to be told. Big vendors run this at scale (Microsoft, OpenAI and AWS all publish theirs); for a small supplier the same three things fit on one page.
Sub-processors of [Your Company Ltd], version [n], [date]
We use the following sub-processors to provide [the service]. We will give [30] days' notice of additions by [email / this page] to customers who have asked to be notified.
For each: Entity (country) | Purpose | Data categories | Hosting region | Transfer mechanism | Agreement | Date added
Or keep it somewhere that maintains it. Rowpa's vendor register holds 400 source-linked entries with the legal entity, DPA link, hosting country and transfer mechanism, re-checked monthly. Your sub-processor list is the vendors you have linked to processing activities, published on your Trust Center at its own address, with a form for customers who want an email when it changes, and included in every supplier pack, with the DPA status shown honestly for each. How the published list works. What else goes in the pack.
Your sub-processor list, from a website scan. Rowpa finds the tools you run, names the entity behind each, and checks the DPA. Free to build.
Scan your site